The affected device identified in the advisory is the Skullcandy Dime 3, model S2DCW, running firmware 1.0.0.28. The most difficult practical issue is remediation. A fixed firmware version has been identified, but owners of affected units have no known consumer-accessible way to install it.
What the Dime 3 flaw allows
The issue is tracked as CVE-2025-20701 and concerns Bluetooth Classic, also called BR/EDR. On the affected Dime 3 firmware, the earbuds accept a new Bluetooth pairing request from an unpaired device even when they are not in pairing mode. There is no requirement for the owner to press a button, approve a request, or otherwise confirm the connection.
That is substantially different from the intended experience of pairing earbuds with a Windows laptop, Android phone, iPhone, tablet, or another source device. Ordinarily, putting earbuds into pairing mode is the owner’s visible signal that a new device should be allowed to connect. Here, the earbuds can reportedly skip that authorization step.
Once the unauthorized device has formed a bond, the consequences are not necessarily limited to one brief interruption. The advisory states that the attacker-created bond becomes trusted and may reconnect automatically. An attacker can interrupt the legitimate owner’s A2DP audio connection, take over the audio session, and access the Hands-Free or Headset profile for live microphone capture.
In plain terms, the demonstrated risk for this particular earbud model is that someone nearby could force their way into the earbuds’ trusted-device list, interfere with what the owner is listening to, and potentially use the earbuds’ microphone through the relevant Bluetooth audio profile.
This is a nearby Bluetooth attack, not a remote takeover
The headline risk needs an important boundary. The attacker must be within Bluetooth radio range and must send a request to the earbuds’ known or discovered Bluetooth Classic address. No previous pairing or physical possession of the earbuds is required, but physical proximity is.
That means this is not an attack someone can launch from anywhere on the Internet merely because they know a Dime 3 owner’s email address, phone number, or Windows account. It is a local wireless exposure. Locations where an unknown person can remain relatively close to a target—shared offices, transit, cafés, classrooms, venues, apartment common areas, and similar spaces—are the more relevant setting.
Address discovery can also be an operational consideration for an attacker in some situations. The available evidence establishes that the address may be known or discovered, but it does not justify treating discovery as effortless in every real-world scenario. Proximity remains the central requirement.
That limitation should not be mistaken for a reason to dismiss the problem. Bluetooth accessories are designed for use around other people, and earbuds are often worn in places where users cannot easily notice an attempted connection. The lack of a required pairing mode or owner confirmation is what makes the defect consequential.
The confirmed scope is narrower than the SDK issue
The directly verified product finding is specific: Skullcandy Dime 3 model S2DCW running firmware 1.0.0.28. Owners should not assume that every Skullcandy product, every Dime-branded product, or even every Dime 3 unit has been individually confirmed to share this behavior.
At the same time, the Dime 3 finding has been associated with an underlying Airoha Bluetooth audio software development kit authorization flaw. The reported affected SDK ranges include Bluetooth-audio IoT SDK version 5.5.0 and earlier, plus AB1561x, AB1562x, and AB1563x SDK version 3.3.1 and earlier.
That is meaningful context, but it is not a consumer-product inventory. An SDK can be used in many devices, with varying firmware versions, feature sets, Bluetooth configurations, and vendor changes. It would be inaccurate to label every product that may use an Airoha component vulnerable without device-specific confirmation.
The severity record associated with the CVE includes a CVSS 3.1 score of 8.8, rated High, in a CISA enrichment. That score is a useful signal that the underlying weakness deserves attention, but it is not a prediction that every owner will be attacked. It also should not be confused with an assertion that all Bluetooth products based on the affected SDK have the same practical impact as the Dime 3.
Do not overstate the phone-data risk
The confirmed Dime 3 impacts are serious on their own: unauthorized persistent bonding, disruption of the legitimate audio connection, audio-session takeover, and possible live microphone access through the Hands-Free or Headset profile.
Broader claims sometimes attached to Bluetooth headset research need more care. Research into other Airoha-based devices has described additional functionality and multi-step attack chains that could involve phone-facing services. However, the Dime 3 advisory makes access to other services conditional on the device’s capabilities. The reviewed evidence does not establish, for this Skullcandy model, that an attacker can obtain contacts or call history, impersonate the headset to a phone, or issue hands-free commands.
For Windows users, the practical concern is therefore primarily the accessory itself. A nearby rogue device may interfere with the earbuds and use their audio and microphone functions; the evidence does not demonstrate a compromise of a Windows PC, a Microsoft account, or the contents of the paired phone. Removing and re-adding the earbuds in Windows Bluetooth settings also should not be treated as a verified repair for a bond that may have been created directly on the earbuds.
The patch exists, but the owner update path does not
Firmware version 1.0.0.30 is considered an effective patch for the Dime 3 issue. The problem is that affected units on version 1.0.0.28 have no known consumer-accessible update method.
Skullcandy’s support material separately says Dime 3 does not support the Skullcandy App or the Skull-iQ App. In the available material, there is no public manufacturer-provided way for customers to inspect whether their earbuds are running 1.0.0.28 or 1.0.0.30, and no identified app route for moving an existing affected unit to the newer firmware.
This distinction is crucial. It is well supported that the patch version exists and that an affected owner lacks a known public update route. It is not established which manufacturing dates, serial ranges, store inventories, or retail listings might contain patched units. Claims that fixed firmware is limited to newly produced earbuds go beyond what the available primary evidence confirms.
Nor do the reviewed materials establish whether Skullcandy offers a replacement, repair, or alternate servicing channel. Owners should not assume that no such route exists, but they also should not assume a standard reset or normal re-pairing process resolves the vulnerability. Neither has been publicly validated as a mitigation for this specific flaw.
Practical choices for Dime 3 owners
If you own a Dime 3, first confirm the model marking rather than relying on a product name in a retailer listing. The identified device is model S2DCW, and the confirmed vulnerable firmware is 1.0.0.28. Because a public owner-facing firmware check is not established, asking Skullcandy support or the retailer to verify the firmware and available remedy is reasonable.
For people who use these earbuds in privacy-sensitive contexts, the most dependable near-term risk reduction may be a usage decision rather than a software setting. Consider using another headset for calls involving confidential work, personal health information, financial matters, or other conversations where the possibility of unauthorized microphone access is unacceptable. A wired headset avoids this particular Bluetooth pairing exposure altogether.
Windows users should also avoid assuming that a PC-side action patches an earbud-side flaw. Keeping Windows current remains good security practice, but Windows Update cannot be presumed to replace the Dime 3’s embedded firmware. Likewise, changing a PC’s Bluetooth configuration may reduce how often the PC is exposed to ordinary wireless risks, but it is not documented as a fix for the earbuds’ acceptance of unauthorized Bluetooth Classic pairing.
If the earbuds are still within a retailer return period, owners who cannot obtain a firmware-status answer may reasonably weigh return or replacement options against their personal risk tolerance. That is particularly relevant for users who depend on the microphone for work calls or routinely use the earbuds around unfamiliar people.
A reminder that earbuds need a real update strategy
The Dime 3 case illustrates a recurring weakness in low-cost connected accessories: a security fix is of limited value when customers cannot obtain it. Firmware is part of the security boundary for Bluetooth headphones, not merely a source of sound-quality improvements or new features.
It also raises a purchasing question for Windows and mobile users. Before buying wireless audio gear, app support and update support may be as important as codec support, battery life, or multipoint pairing. A product that cannot receive customer-installed security updates can leave buyers dependent on inventory turnover, service channels, or replacement decisions when a serious defect surfaces.
There is related evidence that CVE-2025-20701 has attracted attention beyond Skullcandy: Apple issued a Beats Studio Buds firmware update that cited the same CVE. But the researchers who examined the Beats behavior later cautioned that its insecure pairing window was not necessarily the identical issue, even if a shared root cause is possible. That comparison reinforces the need to judge each product on its own technical evidence rather than assume a CVE label alone proves identical behavior across brands.
For the Dime 3, the core facts are already enough to warrant action: a nearby device may pair without authorization on the confirmed affected firmware, the resulting bond can persist, and a consumer update route for existing affected units is not known. Until Skullcandy provides a clear way to identify and remediate affected earbuds, owners should make their use decisions with that limitation in mind.